What is ISO/IEC 21878 about?
ISO/IEC 21878 specifies security guidelines for the design and implementation of virtualized servers (VSs). Design considerations focusing on identifying and mitigating risks, and implementation recommendations with respect to typical VSs are covered in ISO/IEC 21878.
Note: ISO/IEC 21878 is not applicable to:
- desktop, OS, network, and storage virtualization; and
- vendor attestation
Who is ISO/IEC 21878 for?
ISO/IEC 21878 on security techniques is useful for:
- Organizations using virtualized servers (VSs)
- Providers of virtualized servers (VSs)
Why should you use ISO/IEC 21878?
Data centre infrastructures are rapidly becoming virtualized due to the increasing deployment of virtualized servers (VSs) for cloud computing services and for internal IT services. Since VSs are compute engines hosting many business-critical applications, they are key resources to be protected in virtualized data centre infrastructure. As virtualized servers (VSs) are becoming mainstream in typical data centre infrastructure setups, the secure design and implementation of virtualized servers (VSs) forms an important element in the overall security strategy.The purpose of ISO/IEC 21878 is to provide security guidelines for the design and implementation of virtualized servers (VSs). The motivation for ISO/IEC 21878 is the global trend in enterprises and government agencies deploying server virtualization technologies within their internal IT infrastructure as well as the use of virtualized servers (VSs) by
cloud service providers. Hence the target audience is any organization using and/or providing virtualized servers (VSs). The intended goal of this document is to facilitate informed decisions with respect to architecting VS configurations. Such design and implementation configuration is expected to assure the appropriate protection for all virtual machines (VMs) and the application workloads running in them in the entire virtualized infrastructure of the organization.